Commit Graph

1175 Commits

  • feat(usage): app-aware hero icon and neutral Codex theme
    - Replace the fixed Zap glyph in the usage hero with the selected app's
      brand icon via a new AppGlyph component, reusing APP_ICON_MAP
      (cloneElement scales 14px -> 20px); falls back to Zap for the "all" view.
    - Recolor the Codex title theme from emerald to neutral gray to match
      OpenAI's monochrome branding. neutral-500/10 stays visible in both
      light and dark modes, unlike a flat black tint.
  • fix: usage script provider credential resolution (#1479)
    The JS-script usage path resolved {{apiKey}}/{{baseUrl}} with env-only
    field guessing, so apps that store credentials elsewhere (Codex:
    auth.OPENAI_API_KEY + config.toml base_url) always got empty values and
    custom-template queries failed despite a fully configured provider.
    
    - query_usage / test_usage_script now delegate to
      Provider::resolve_usage_credentials, the same per-app resolver used by
      the native balance/coding-plan path and mirrored by the frontend
      getProviderCredentials; explicit non-empty script values still win
    - test_usage_script loads the provider and applies the same fallback,
      so testing matches what a saved script does
    - the custom-template variable preview shows the effective values
      (script overrides first, then provider config) instead of always
      showing provider credentials
    - extract_codex_base_url documents and test-locks the frontend-mirror
      invariant: non-active [model_providers.*] sections are never read
    
    Reworked from the original patch to reuse the existing resolver instead
    of duplicating per-app extraction.
    
    Co-authored-by: Jason <farion1231@gmail.com>
  • fix(presets): add Kimi affiliate links (#3809)
    Problem: Kimi and Moonshot preset links were user-clickable without the cc-switch affiliate query.\n\nDecision: Update only UI-facing preset website/API-key links and leave API request endpoints untouched.\n\nChange: Add aff=cc-switch to Kimi/Moonshot websiteUrl values and Codex/OpenCode API-key links.
    
    Co-authored-by: xumingyuan <xumingyuan@msh.team>
  • refactor(presets): align CCSub to end of partner block across apps
    Move the CCSub preset to sit right after DouBaoSeed, at the end of the
    partner block and before the first non-partner provider, so its position
    is consistent across all six apps:
    
    - Codex / OpenCode: moved up from the 2nd slot (between Shengsuanyun and
      the next partner) to the block tail
    - OpenClaw / Hermes: moved up from the aggregator section to the block tail
    - Claude / Claude Desktop: already at the block tail
    
    Also add the missing CHANGELOG entry for the CCSub preset, and drop the
    provider preset order test that enforced a now-unneeded ordering invariant.
  • feat(presets): add CCSub provider across six apps
    Add CCSub, a multi-model aggregator partner, as a preset for Claude, Codex, OpenCode, OpenClaw, Claude Desktop, and Hermes. Each preset carries the referral signup link as apiKeyUrl.
    
    - Register the ccsub icon via iconUrls (1.1MB SVG URL import) + metadata
    - Add partnerPromotion copy in zh/en/ja
    - List CCSub in the sponsor section of all README locales
    - Use gpt-5.5 and gemini-3.1-pro as the OpenAI/Gemini model ids
  • fix(providers): only block explicit official providers under proxy takeover
    The proxy-takeover block previously fell back to the isOfficial heuristic
    (empty base_url / missing key) when category was absent. That misjudged
    custom providers whose endpoint lives in meta or whose fields are simply
    unfilled: their switch button got disabled, making users think the config
    was broken. That extra UI block was also "virtual" — the executor in
    useProviderActions only ever honored category === "official", so the
    front end blocked more than the backend would enforce.
    
    Gate the block solely on explicit category === "official", matching the
    executor and unifying both verdicts on a single source of truth.
    
    Also rework the blocked-state UI:
    - drop the red "blocked" badge for a plain disabled Enable button
    - move title/cursor onto a wrapper span (disabled buttons set
      pointer-events:none, so an on-button title/cursor never fired)
    - replace the account-ban warning tooltip with a lighter hint
      (provider.blockedByProxyHint), four locales kept in sync
  • chore(presets): update SSSAiCode domain and endpoint nodes
    Switch website/apiKey URLs to sssaicodeapi.com and replace base URL
    nodes with node-hk.sssaicodeapi.com (default), node-hk.sssaiapi.com,
    and node-cf.sssaicodeapi.com across all 7 app presets.
  • [codex] Fix VS Code session previews (#3593)
    * Fix Codex VS Code session previews
    
    * fix(codex): use last IDE request heading for session previews
    
    A markdown heading inside the active selection / open file could precede the real injected request, so matching the first "## My request for Codex:" heading picked selection content instead of the user prompt. Scan for the last matching heading (the IDE injects the real request as the final section) on both the Rust title path and the frontend TOC preview path.
    
    Add regression tests for the selection-heading case, and pin the known best-effort limitation when the request body itself repeats the heading.
    
    ---------
    
    Co-authored-by: Jason <farion1231@gmail.com>
  • fix(opencode): use OpenAI-compatible SDK for APINebula preset
    APINebula is an OpenAI-compatible relay (its base URL ends in /v1, matching
    its Codex/OpenClaw/Hermes presets), but the OpenCode preset loaded the
    @ai-sdk/openai package, which targets the OpenAI Responses API and fails
    against chat-completions-only upstreams. Switch the npm field to
    @ai-sdk/openai-compatible so requests use the OpenAI Chat Completions format.
  • feat(usage): add official subscription quota template with unified tier rendering
    Changes:
    - Add official_subscription template type for Claude/Codex/Gemini
    - Replace implicit 'category=official auto-query' with explicit opt-in template
    - Default disabled; users enable via usage script modal with configurable interval
    - Unify tier→label mapping across subscription and script paths via labeled_tier_parts()
    - Fix tray rendering: week aliases (seven_day/opus/sonnet) now use highest utilization
    - Add depth guard: official_subscription checks enabled flag in query_provider_usage_inner
    - Add cache invalidation symmetry: invalidate_subscription() for disabled providers
    - i18n: add templateOfficialSubscription + hint in zh/en/ja/zh-TW
    
    Backend (Rust):
    - provider.rs: add TEMPLATE_TYPE_OFFICIAL_SUBSCRIPTION branch, flatten SubscriptionQuota→UsageData
    - tray.rs: extract labeled_tier_parts() shared by both summary functions, use max_by for multi-alias groups
    - usage_cache.rs: add invalidate_subscription() method
    - Test coverage: add week-alias highest-utilization tests for both paths
    
    Frontend (TypeScript):
    - UsageScriptModal: add official_subscription to templates, auto-detect for official providers
    - ProviderCard: gate useUsageQuery with !isOfficialSubscriptionUsage, pass autoQueryInterval to footer
    - SubscriptionQuotaFooter: accept autoQueryInterval prop, default 0 (disabled)
    - constants.ts: add TEMPLATE_TYPES.OFFICIAL_SUBSCRIPTION
    
    Fixes tier rendering regression where:
    - Claude/Codex: seven_day was missed (only weekly_limit matched) → lost 7-day window in tray
    - Gemini: gemini_pro/flash/flash_lite fell through to fallback → leaked machine names
    - Multi-window (opus+sonnet): find() took first, not worst → underestimated utilization and emoji color
    
    All tests pass (cargo test + cargo clippy clean).
  • fix: polish usage statistics ui (#3426)
    * fix: improve usage statistics ui
    
    * chore: remove unused token suffix translation
    
    ---------
    
    Co-authored-by: Jason <farion1231@gmail.com>
  • fix: disable auto-capitalize on Input component for macOS (#3626)
    Add autoComplete, autoCorrect, autoCapitalize, and spellCheck attributes
    to prevent macOS from auto-capitalizing the first letter in input fields.
  • feat(usage): add OpenCode session usage sync (#3215)
    * feat(usage): add OpenCode session usage sync
    
    Add OpenCode as a fourth app type in the usage statistics system.
    Reads per-message token data from opencode's local SQLite database
    (~/.local/share/opencode/opencode.db) and imports into proxy_request_logs.
    
    - New session_usage_opencode.rs module following Codex/Gemini pattern
    - Parses assistant message.data JSON for tokens, cost, model
    - Adds "opencode" to AppType union and filter tabs
    - Updates dedup filters to include opencode_session data_source
    - Adds i18n keys for all 4 locales
    
    * fix(usage): add opencode to UsageHero title themes
    
    * fix: respect XDG_DATA_HOME and platform defaults for OpenCode DB path
    
    - Support OPENCODE_DB env var override (absolute and relative paths)
    - Use ~/Library/Application Support/opencode/ on macOS
    - Use XDG_DATA_HOME/opencode/ when set
    - Fall back to ~/.local/share/opencode/ on Linux
    - Rename misleading test to test_parse_message_data_ignores_role
    
    * fix(usage): use ~/.local/share/opencode on all platforms
    
    OpenCode relies on xdg-basedir, which ignores macOS/Windows conventions,
    so its DB always lives at ~/.local/share/opencode. The previous macOS
    default pointed at ~/Library/Application Support/opencode, which does not
    exist, making the sync a silent no-op for macOS users without
    XDG_DATA_HOME set.
    
    * fix(usage): include opencode -wal mtime in freshness check
    
    OpenCode runs its SQLite DB in WAL mode; new commits land in the -wal
    file and the main DB file's mtime only advances on checkpoint. Keying
    the freshness gate solely on opencode.db could skip newly written
    sessions until a checkpoint occurred. Take the max of the db and -wal
    mtimes instead.
    
    * style(usage): apply cargo fmt to opencode session sync
    
    Fixes Backend Checks cargo fmt --check failure.
    
    Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
    
    * fix(usage): ignore empty OPENCODE_DB and XDG_DATA_HOME env vars
    
    An empty OPENCODE_DB collapsed the path to the data dir (dropping the opencode.db filename); an empty XDG_DATA_HOME produced a relative "opencode" path. Treat empty strings as unset, per the XDG spec.
    
    Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
    
    * fix(usage): harden OpenCode session sync error handling and labeling
    
    - Map '_opencode_session' provider_id to 'OpenCode (Session)' display name
    - Return accurate inserted flag from insert_opencode_message (was always true)
    - Do not advance file/session sync_state when a session errors, so failed
      inserts are retried next run instead of being permanently skipped
    - Surface per-message insert failures into the sync result errors
    - Add opencode_session data-source icon and i18n labels (zh/zh-TW/en/ja)
    - Add provider-stats labeling test for opencode session rows
    
    * fix(usage): only import finalized OpenCode messages
    
    An in-progress assistant message holds partial tokens; OpenCode updates the same message_id with final values later. Since request_id is fixed and the insert uses INSERT OR IGNORE, a partial row could never be corrected. Skip messages without time.completed so each turn is imported once with final usage.
    
    Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
    
    * fix(usage): keep OpenCode incomplete sessions retryable
    
    ---------
    
    Co-authored-by: Eira Hazel <kip3vx9ma@mozmail.com>
    Co-authored-by: Eria hazel <git config --global user.email your@email.com>
    Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
    Co-authored-by: Jason <farion1231@gmail.com>
  • feat: 新增 S3 兼容云存储同步 (#1351)
    * Add S3 Cloud Sync design document
    
    Design for adding AWS S3 as a new Cloud Sync backend alongside WebDAV.
    Hybrid approach: extract shared sync protocol, add independent S3 transport.
    
    Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
    
    * Add S3 cloud sync implementation design (reqwest + Sig V4)
    
    Updated design based on 2026-03-06 draft: switches from rust-s3 crate
    to hand-rolled AWS Sig V4 on existing reqwest for broader S3-compatible
    service support (AWS, MinIO, R2, Alibaba OSS, Tencent COS, Huawei OBS).
    
    Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
    
    * Add S3 cloud sync implementation plan (11 tasks, TDD)
    
    Detailed step-by-step plan covering: sync_protocol extraction, S3 Sig V4
    transport, settings, sync/auto-sync modules, Tauri commands, frontend
    presets/dynamic form, and i18n.
    
    Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
    
    * deps: add hmac crate for S3 Sig V4 signing
    
    Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
    
    * refactor: extract sync_protocol.rs from webdav_sync.rs for shared use
    
    Move transport-agnostic sync protocol logic (constants, types, snapshot
    building, manifest validation, artifact verification, snapshot application,
    utilities) into a new shared sync_protocol module so both WebDAV and the
    upcoming S3 transport can reuse it.
    
    Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
    
    * fix: use transport-neutral error keys in sync_protocol
    
    Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
    
    * feat: add S3 transport layer with AWS Sig V4 signing
    
    Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
    
    * feat: add S3SyncSettings to AppSettings
    
    Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
    
    * feat: add S3 sync module with upload/download/fetch
    
    Implements the S3 sync protocol layer (s3_sync.rs) that combines the
    shared sync_protocol with the S3 transport. Mirrors the WebDAV sync
    module structure with independent sync mutex, connection check,
    upload, download, fetch_remote_info, and sync status persistence.
    
    Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
    
    * feat: add S3 auto sync worker with debounce
    
    Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
    
    * feat: add S3 sync Tauri commands and auto sync worker startup
    
    Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
    
    * feat: add S3 sync TypeScript types and API layer
    
    Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
    
    * feat: add S3 sync i18n translations (en/zh/ja)
    
    Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
    
    * feat: add S3 sync presets and dynamic form to sync settings
    
    Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
    
    * fix: preserve HTTP scheme for S3 custom endpoints (MinIO support)
    
    Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
    
    * test: add live S3 integration tests (env-var driven, --ignored)
    
    Run with: S3_TEST_AK=... S3_TEST_SK=... S3_TEST_BUCKET=... cargo test --lib services::s3::integration_tests -- --ignored
    
    Verifies test_connection, put_object, get_object, head_object, and 404
    handling against a real S3 bucket using the project's own Sig V4 signing.
    
    Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
    
    * chore: remove internal design docs before PR
    
    * fix: wire S3 auto-sync to DB hook & sync UI state on async load
    
    - P1: Add s3_auto_sync::notify_db_changed call in SQLite update_hook
      so S3 auto-sync worker receives DB change signals (was only wired
      for WebDAV, leaving S3 worker idle)
    
    - P2: Add useEffect to update syncType selector when s3Config loads
      asynchronously, preventing stale "webdav" default for S3 users
    
    * fix: satisfy clippy for s3 sync
    
    * fix: address s3 sync review feedback
    
    ---------
    
    Co-authored-by: Keith (via OpenClaw) <keithyt06@users.noreply.github.com>
    Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
    Co-authored-by: Jason <farion1231@gmail.com>
  • Add media fallback rectifier for text-only models
    Replace unsupported Anthropic image blocks with an [Unsupported Image] marker when routed models are text-only or upstream rejects image input.
    
    Add rectifier settings for media fallback and heuristic model detection, wire the controls into the settings UI, and cover the sanitizer and forwarder gates with regression tests.
  • feat: add CherryIN preset provider for Claude Code and Codex (#3643)
    * feat: add CherryIN preset provider for Claude Code and Codex
    
    CherryIN (open.cherryin.net) is an API aggregator gateway. Add it as a quick-config preset for both Claude Code (Anthropic format) and Codex (OpenAI-compatible), placed next to AiHubMix, with the official brand icon. Endpoints and model IDs verified against CherryIN's live pricing API.
    
    * feat: add CherryIN preset to Gemini, Claude Desktop, OpenCode, OpenClaw, Hermes
    
    Extend CherryIN coverage to all remaining apps, each placed next to AiHubMix. Anthropic-native (open.cherryin.net) for Claude Desktop/OpenClaw/Hermes, @ai-sdk/anthropic (/v1) for OpenCode, Gemini-compatible endpoint for Gemini CLI. Model IDs verified against CherryIN's live pricing API.
  • [codex] fix Zhipu coding plan presets (#3524)
    * fix(presets): update Zhipu coding plan endpoints
    
    * fix(model-fetch): probe /models on versioned /vN base URLs
    
    The model-list probe assumed any base URL not ending in /v1 needs /v1/models appended. For providers whose base URL already ends in a version segment like /v4 (Zhipu/Z.AI GLM Coding Plan at .../api/coding/paas/v4), this produced .../v4/v1/models which 404s, so the "Fetch models" button always failed.
    
    Detect a trailing /v{N} version segment and probe {base}/models first, keeping /v1/models as a fallback candidate for non-/v1 versions. Fixes Codex/OpenCode/OpenClaw/Hermes GLM presets and any other vN-style endpoint, with no behavior change for /v1 or non-versioned URLs.
    
    ---------
    
    Co-authored-by: Jason <farion1231@gmail.com>
  • feat: 新增 ZenMux Token Plan 供应商,支持手动凭证与 USD 额度富展示 (#2709)
    * feat(Token plan): 增加 ZenMux 支持
    
    * chore: format code with prettier
    
    * chore: format code with cargo fmt
    
    ---------
    
    Co-authored-by: 明桓 <jihaodong.jhd@oceanbase.com>
    Co-authored-by: Jason <farion1231@gmail.com>
  • Simplify Codex takeover notice copy and match hint styling
    Restyle the proxy-takeover notice in the Codex editor from the boxed
    Alert to the amber inline-hint style used by the endpoint hints, and drop
    implementation jargon (127.0.0.1 / PROXY_MANAGED) that users could not
    interpret. The notice and the auth/config hints now simply state that the
    form shows the stored provider config rather than the proxy-managed live
    config. i18n synced across en/zh/ja/zh-TW.
  • Fix Codex edit dialog masking live OAuth during proxy takeover
    The reported "OAuth access token disappears when enabling Codex proxy
    takeover" was a display artifact, not data loss: auth.json on disk kept
    the OAuth login the whole time. During takeover the edit dialog falls
    back to the stored provider config (so it does not surface the proxy
    placeholder), which for a third-party provider shows that provider's own
    key instead of the live auth.json, making the OAuth token look gone.
    
    Thread an isProxyTakeover flag from App through ProviderForm into the
    Codex editor and show an explicit notice plus storage-aware auth/config
    hints clarifying that the form displays the stored provider config while
    the live config is temporarily managed by the proxy. Drop the
    proxy-running condition so the notice shows whenever takeover is active,
    even with the proxy stopped.
    
    Add a regression test asserting the dialog does not read live settings
    during takeover and renders the database config. i18n synced across
    en/zh/ja/zh-TW.
  • Fix Codex model catalog being wiped by live-config backfill
    `modelCatalog` is a cc-switch-private field whose SSOT is the database; Live's
    config.toml only carries a lossy `model_catalog_json` projection. Proxy
    takeover/restore cycles and the official Codex.app rewriting config.toml can
    drop that projection, so `read_live_settings` reconstructs an empty catalog.
    Two paths then overwrote the stored mapping with that empty Live snapshot:
    
    - Switch-away backfill (`switch_normal` -> `restore_live_settings_for_provider_backfill`):
      now overlays the DB provider's `modelCatalog`, falling back to the
      Live-reconstructed one only when the DB has none.
    - Edit dialog (`EditProviderDialog`): when editing the active Codex provider it
      preferred Live over the DB SSOT; now keeps the DB `modelCatalog` so opening +
      saving no longer clears the mapping table.
    
    Add Rust backfill tests (preserve DB catalog when Live lacks it; keep Live
    catalog when DB has none) and a frontend regression test for the edit dialog.
  • fix(usage): resolve per-app credentials for native balance/coding-plan queries (#3355)
    * fix(usage): resolve per-app credentials for native balance/coding-plan queries
    
    The native usage-query paths (balance + coding_plan) in
    `query_provider_usage_inner` read credentials only from `env.ANTHROPIC_*`.
    That matches Claude providers, but Codex stores its key in
    `auth.OPENAI_API_KEY` with the base URL inside a TOML `config` string,
    Hermes/OpenClaw flatten them at the top level, and OpenCode nests them under
    `options`. So the card "refresh usage" / auto-query returned empty
    credentials and failed ("查询失败") for those apps, even though the
    config-page "Test" button worked (the frontend extracts per-app correctly).
    
    Introduce a single per-app resolver `Provider::resolve_usage_credentials`
    that mirrors the frontend `getProviderCredentials`, and route both native
    branches through it. Add `extract_codex_base_url` to `codex_config` as the
    canonical Codex TOML base-URL parser and make the proxy adapter delegate to
    it (removing a duplicate copy). Align the frontend `getProviderCredentials`
    to cover OpenCode and Claude Desktop and to use the same OpenRouter/Google
    key fallbacks as the backend.
    
    Fixes #3158
    Fixes #3100
    Fixes #2625
    
    * refactor(usage): explicit AppType arms + frontend trailing-slash trim
    
    Address two review nits on the per-app credential resolver:
    
    - provider.rs: replace the catch-all `_` arm in resolve_usage_credentials with an explicit `AppType::Claude | AppType::ClaudeDesktop` arm, so a new AppType variant fails to compile here instead of silently defaulting to the Anthropic env shape.
    - UsageScriptModal.tsx: normalize getProviderCredentials baseUrl through a single trailing-slash trim so the frontend 'Test' path matches the backend resolver (trim_end_matches), keeping front/back truly in lockstep.
    
    No behavior change for well-formed configs; tests/typecheck/fmt/clippy clean.
    
    * fix(usage): skip empty primary credential fields in fallback chain
    
    `obj.get(key)` returns `Some` for a present-but-empty field, so the
    `.or_else()` fallback chains for the Claude/ClaudeDesktop and Gemini api-key
    lookups only skipped *absent* keys, not empty ones. Presets seed fields like
    `ANTHROPIC_AUTH_TOKEN` as present-but-empty placeholders, so a provider whose
    real key lives in a fallback field (`ANTHROPIC_API_KEY` / `OPENROUTER_API_KEY`
    / `GOOGLE_API_KEY`, or `GOOGLE_API_KEY` for Gemini) resolved to an empty key on
    the native balance/coding-plan path — while the frontend `a || b` (which skips
    empty strings) still found it, reproducing the same Test-works / refresh-fails
    divergence this PR removes.
    
    Add a `first_non_empty` helper that skips present-but-empty values, matching
    the frontend `||` semantics, and use it for both fallback chains. Tests cover
    empty primary + populated fallback for Claude and Gemini.
  • fix: Claude Desktop 官方供应商添加报错 #3402 (#3405)
    * fix: Claude Desktop 官方供应商添加时缺少 ANTHROPIC_BASE_URL 报错
    
    根因:前端 mutation 为 claude-desktop 生成随机 UUID 作为 provider id,
    后端 is_official_provider 通过 id 匹配跳过校验,随机 UUID 不匹配导致
    走入普通 direct 模式校验并要求 ANTHROPIC_BASE_URL。
    
    修复:
    - 前端:claude-desktop + category=official 时使用固定 id "claude-desktop-official"
    - 后端:validate_provider / validate_direct_provider / validate_proxy_provider /
      apply_provider_to_paths 增加 category=="official" 兜底检查
    
    Fixes #3402
    
    * fix: restrict Claude Desktop official provider detection
    
    * fix: add Claude Desktop official provider via seed
    
    ---------
    
    Co-authored-by: 金恩光 <enguang.jin@gmail.com>
    Co-authored-by: Jason <farion1231@gmail.com>
  • Fix Codex OAuth auth being cleared during preserve-mode takeover
    When "preserve official auth on switch" is enabled, proxy takeover routes
    the PROXY_MANAGED placeholder into config.toml's experimental_bearer_token
    and leaves auth.json (the ChatGPT OAuth login) untouched. Takeover detection
    only inspected auth.json's OPENAI_API_KEY, so it never recognized this state
    and returned a false negative, which led downstream paths to clobber the
    preserved OAuth login.
    
    - Detection: is_codex_live_taken_over now also matches a config.toml
      experimental_bearer_token equal to the placeholder, fixing detect/cleanup/
      restore/startup-recovery in one place.
    - Cleanup: remove the config.toml bearer token only when it equals the
      placeholder (new remove_codex_experimental_bearer_token_if predicate), so a
      real third-party key is never stripped.
    - Write: under preservation, the None-provider takeover path writes only
      config.toml and keeps auth.json intact, matching the provider path.
    - Settings: rename the section to "Codex App Enhancements" and reword the
      description across all four locales.
    - Add tests covering OAuth preservation on takeover and placeholder-only
      cleanup.
  • Default Codex auth preservation to off (opt-in)
    Flip preserve_codex_official_auth_on_switch from true to false so
    third-party Codex switches overwrite auth.json by default, matching the
    expectation that switching providers also swaps credentials. Users who
    rely on keeping the ChatGPT login in auth.json while on a third-party
    provider (for official plugins / remote login) can enable it in
    Settings -> Codex Authentication.
    
    The toggle field ships for the first time here (it is not in v3.16.0),
    so no existing settings.json holds an explicit value -- every user lands
    on the new default and no migration is required.
    
    Also set the flag explicitly in the preservation unit test instead of
    relying on the global default, keeping it valid now that the default is
    false.
  • Align Claude Desktop model mapping with Claude Code three-role tiers
    Claude Desktop's 3P validation only accepts claude-{sonnet,opus,haiku}-*
    role IDs, so providers must map every tier. Bring the Desktop mapping flow
    in line with Claude Code and fix the fallout that broke sub-agent Haiku calls.
    
    - Proxy form: replace the dynamic route list with fixed Sonnet/Opus/Haiku
      tiers; blank tiers backfill from the first filled tier (Sonnet first) on
      submit and inherit its supports1m flag
    - Backend: add a role-keyword fallback in map_proxy_request_model so dated
      official names (e.g. claude-haiku-4-5-20251001) resolve to the right tier,
      guarded by is_claude_safe_model_id so [1m]-suffixed IDs stay rejected
    - Tighten is_claude_safe_model_id / isClaudeSafeRoute to reject degenerate
      role IDs like "claude-sonnet-"
    - Fix the seed-effect race where normalizing empty routes to three blank
      tiers blocked the default-route backfill
    - Sync switch hints, placeholders, and the zh/en/ja/zh-TW locales to the
      three-role-ID rule
    - Update zh/en/ja user manual (2.1, 2.6), calling out legacy Claude IDs
      (claude-3-5-sonnet-...) as a rejected example
    
    Tests: 282 frontend + 34 backend claude_desktop; typecheck, clippy, fmt clean.
  • Rename OpenCode Go preset to drop model suffix
    Simplify the display name from "OpenCode Go (DeepSeek V4 Flash)" to
    "OpenCode Go" in both the Claude Code and Claude Desktop preset lists.
  • Add referral param to ShengSuanYun website links
    The websiteUrl for ShengSuanYun presets pointed at the bare domain while
    only apiKeyUrl carried the from=CH_4HHXMRYF referral code. Append the same
    referral param to websiteUrl across all provider presets so the in-app
    'open website' jump is also attributed to the channel.
  • Update default models and pricing across presets
    Bump default model names project-wide: gpt-5.4 -> gpt-5.5,
    gemini-3.x -> gemini-3.5-flash, glm-5 -> glm-5.1, and
    grok-code-fast-1 -> grok-build-0.1 across all provider presets
    (claude, codex, gemini, hermes, openclaw, opencode, universal),
    Gemini config, and stream check defaults.
    
    Pricing:
    - Seed gemini-3.5-flash, gemini-3.1-flash-lite, step-3.5-flash-2603,
      doubao-seed-2.0-code, mimo-v2.5(/pro), qwen3-coder-480b, grok-build-0.1.
    - Correct deepseek-v4-flash/pro, glm-5/5.1, grok pricing.
    - Add repair_current_model_pricing: idempotent pass that fixes only
      rows still equal to the outdated built-in values, preserving any
      user-customized prices (seed uses INSERT OR IGNORE and cannot update
      existing rows).
    
    Fixes from review:
    - opencode: drop duplicate gemini-3.5-flash variant (unreachable via
      .find), keep the entry with the full minimal/low/medium/high set.
    - Align stale display names/costs to gemini-3.5-flash (hermes, openclaw,
      opencode); openclaw cost -> {1.5, 9, 0.15} to match seed.
    - i18n (zh/en/ja/zh-TW): refresh OMO category tooltips for new model
      names; fix writing tooltip to Kimi K2.5 to match its recommended.
    
    Update tests accordingly and add a regression test asserting unique
    model ids in the Google opencode preset variants.
  • Upgrade default Claude Opus model to 4.8
    Bump the default Opus route/model from claude-opus-4-7 to claude-opus-4-8
    across provider presets (claude, claudeDesktop, hermes, openclaw, opencode,
    universal), i18n locales (zh/en/ja/zh-TW), pricing seed data, and the
    user-manual docs.
    
    - Add claude-opus-4-8 pricing row ($5/$25/$0.50/$6.25); keep the 4-7 row
      for historical usage stats (seeded via INSERT OR IGNORE).
    - Claude Desktop proxy: accept bidirectional opus 4-7 <-> 4-8 route alias
      during rollout so previously saved routes keep resolving.
    - thinking_optimizer: route opus-4-8 through adaptive thinking and normalize
      dotted model ids (also fixes dotted 4-6/4-7 falling back to legacy).
    - usage_stats: normalize Bedrock/Vertex/aggregator opus-4-8 ids to base
      pricing.
    
    Also merge role:"system" messages into the Gemini systemInstruction in the
    Anthropic->Gemini transform.
  • feat(usage): real-time stats refresh + fix codex sync panic on non-ASCII model names (#3027)
    The usage dashboard previously only refreshed on app restart for users
    who don't route through the cc-switch proxy. Two issues were involved:
    
    1. The session-sync background task panicked when a Codex model name
       contained non-ASCII characters (e.g. `【官】glm-5.1`), because
       `normalize_codex_model` sliced `&name[name.len() - 11..]` without
       verifying char boundaries. Once the task panicked, no session logs
       were imported until the app was restarted (where startup-time
       `rollup_and_prune` happened to flush pending data).
    
    2. Even with sync working, the dashboard only polled every 30s and
       skipped polling when the window was unfocused, so freshly-imported
       data was invisible until the next poll or window refocus.
    
    Fixes
    -----
    
    * `normalize_codex_model`: guard the 11-byte ISO-date suffix slice with
      `is_char_boundary` + `is_ascii` checks. ASCII-only suffix means the
      date-stripping logic is correct, and non-ASCII names (which can never
      be valid date suffixes anyway) now bypass the slice safely.
    
    * New `usage_events` module that emits `usage-log-recorded` to the
      frontend whenever `proxy_request_logs` actually gains a new row.
      Sources covered: proxy `log_request`, Claude/Codex/Gemini session
      sync, and startup `rollup_and_prune`. Notifications use a global
      `OnceLock<AppHandle>` so call sites that don't already hold an
      `AppHandle` (e.g. `UsageLogger`) can notify without signature churn.
    
    * 200ms debounce in `notify_log_recorded` collapses bursts (a single
      Codex sync importing 3000+ entries triggers ~2 emits, not 3000) so
      the frontend's `invalidateQueries` is never spammed.
    
    * Frontend `useUsageEventBridge` listens for the event and invalidates
      `usageKeys.all`. Hook is mounted only on `UsageDashboard`, so the
      listener is unsubscribed automatically when the user navigates away.
    
    Verification
    ------------
    
    * `cargo check` passes (existing 25 dead-code warnings in
      `commands/misc.rs` are pre-existing and unrelated).
    * `tsc --noEmit` passes.
    * Manually verified end-to-end: a Codex sync run that imported 3145
      entries produced 2 debounced emits, both logged as `emit
      usage-log-recorded 成功`, and the dashboard updated within ~200ms.
    
    Behaviour notes
    ---------------
    
    * `INSERT OR IGNORE` paths (Claude/Codex session sync) only notify when
      the row is actually inserted, so dedup-skipped writes don't trigger
      empty refreshes.
    * Gemini's `INSERT … ON CONFLICT … DO UPDATE` path reuses the existing
      `conn.changes() > 0` check and only notifies when token counts truly
      changed.
    * `rollup_and_prune` notifies once per pruning cycle (at most once per
      app start) so the dashboard reflects the new aggregate state.
    
    Co-authored-by: in30mn1a <in30mn1a@users.noreply.github.com>
  • fix(about): handle prerelease tools in version check
    Use semver comparison instead of string inequality so locally-ahead prerelease builds aren't misreported as outdated; backend now fetches the full npm dist-tags and, when the local version leads latest, surfaces the tool's prerelease channel (claude=next) as latest.
  • refactor(codex): unify custom model_provider routing key to "custom"
    - Always emit `model_provider = "custom"` from deep link, UniversalProvider, and the universal form modal so future writes share one stable routing key.
    - Add `codex_provider_template_v1` local migration that rewrites legacy keys (aihubmix/ccswitch/...) under `[model_providers.custom]`, updates profile refs, and backs up the original settings_config under `~/.cc-switch/backups/<timestamp>/providers/`.
    - Tighten history migration source detection to a whitelist plus `[model_providers.<id>]` existence check so user-authored keys are never rewritten in jsonl/state DB.
    - Encode deep link name/model/endpoint through `toml_edit::Value` so display names containing quotes or backslashes no longer break the generated config.toml.
    - Stabilize provider settings backup filename hash with Sha256 (was process-random SipHash).
  • feat(codex): add remote compaction toggle for third-party providers
    Write model_providers name as "OpenAI" to let Codex attempt remote
    compaction through compatible endpoints. Hidden for official providers.
  • fix(omo): sync recommended models with upstream and improve Fill Recommended feedback
    The Fill Recommended button was misleading — it showed toast.success even
    when most slots couldn't be filled due to model ID mismatches with the
    user's configured providers.
    
    Changes:
    - Sync OMO_BUILTIN_AGENTS/CATEGORIES recommended fields with upstream
      oh-my-openagent model-requirements (gpt-5.4→5.5, kimi-k2.5→claude-sonnet-4-6, etc.)
    - Add toast.warning tier when unmatched >= filled, showing slot:model pairs
      (e.g. "Sisyphus: claude-opus-4-7") so users know exactly what to configure
    - Upgrade fillRecommendedNoMatch to also show examples
    - Add fillRecommendedMostlyUnmatched i18n key (zh/en/ja/zh-TW)
  • Enable Codex goals in provider templates (#3089)
    * Enable Codex goals in provider templates
    
    * feat: add Codex goal mode toggle
    
    - Remove forced goals=true from Codex provider presets and custom templates.
    - Add a Codex provider editor switch that updates [features].goals on demand.
    - Update docs, i18n, and regression coverage for the optional Goal mode flow.
    
    ---------
    
    Co-authored-by: Jason <farion1231@gmail.com>
  • feat(i18n): add Traditional Chinese localization (#3093)
    * Add Traditional Chinese localization
    
    * fix: address zh-TW formatting and token units
    
    - Format `zh-TW.json` with Prettier.
    - Use Traditional Chinese `萬` and `億` units for zh-TW token summaries.
    - Add usage formatting coverage for Traditional Chinese locale aliases.
    
    ---------
    
    Co-authored-by: Jason <farion1231@gmail.com>
  • refactor: replace JSON deep copy with deepClone helper and extract useTauriEvent hook (#3140)
    * refactor: replace JSON.parse(JSON.stringify()) with structuredClone and extract useTauriEvent hook
    
    Replace all `JSON.parse(JSON.stringify())` deep copy patterns with native
    `structuredClone()` across production source (9 occurrences), tests (11
    occurrences), and a hand-rolled `deepClone` utility in providerConfigUtils.ts.
    Add "ES2022" to tsconfig lib for type support.
    
    Extract a `useTauriEvent` hook to eliminate the repeated Tauri event listener
    boilerplate (`useEffect` + `active/disposed` flag + async `listen`) that was
    duplicated across App.tsx (3 listeners) and useUsageCacheBridge.ts. The hook
    handles async registration, race-condition guards, and cleanup automatically.
    
    * fix: add compatible deepClone helper
    
    - Add a shared deepClone helper with a structuredClone runtime guard and fallback.
    - Route clone call sites through the helper.
    - Preserve universal-provider-synced listener ordering and drop the dead-directory diff.
    
    * fix: harden Tauri event handling
    
    - Guard WebDAV sync status events against missing payloads.
    - Preserve settings query invalidation ordering before showing auto-sync errors.
    - Simplify useTauriEvent subscriptions to avoid dependency-driven re-listens.
    
    ---------
    
    Co-authored-by: zcb <zhangchongbiao@qiyuanlab.com>
    Co-authored-by: Jason <farion1231@gmail.com>